Home
HIGH: 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:NCRITICAL: 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N Ver. 2.8.85 and earlier (Ver. 2.8.x series)
affected
Ver. 3.1.43 and earlier (Ver. 3.1.x series)
affected
Ver. 3.0.47 and earlier (Ver. 3.0.x series)
affected
Ver. 2.11.75 and earlier (Ver. 2.11.x series)
affected
Ver. 2.10.63 and earlier (Ver. 2.10.x series)
affected
Ver. 2.9.52 and earlier (Ver. 2.9.x series)
affected
Description
Server-side request forgery vulnerability exists in a-blog cms multiple versions. If this vulnerability is exploited, a remote unauthenticated attacker may gain access to sensitive information by sending a specially crafted request.
Problem types
Server-side request forgery (SSRF)
Product status
References
developer.a-blogcms.jp/blog/news/JVNVU-90760614.html